PROBABLYPWNED

Cybersecurity News & Threat Intelligence

View all →
Four Critical n8n Flaws Enable Unauthenticated RCE
Vulnerabilities3 min read

Four Critical n8n Flaws Enable Unauthenticated RCE

n8n patches CVE-2026-27577, CVE-2026-27493, and two more sandbox escapes. One flaw allows unauthenticated attackers to execute commands via public form endpoints.

Marcus ChenMar 24, 2026
Citrix NetScaler Memory Leak Exposes SAML SSO Secrets
Vulnerabilities3 min read

Citrix NetScaler Memory Leak Exposes SAML SSO Secrets

CVE-2026-3055 (CVSS 9.3) lets unauthenticated attackers read sensitive data from NetScaler memory. Affects appliances configured as SAML Identity Providers—patch now.

Marcus ChenMar 24, 2026
Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild
Vulnerabilities3 min read

Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild

Attackers exploiting CVE-2025-32975 authentication bypass in Quest KACE to hijack admin accounts and deploy credential harvesters. Patched in May 2025—many remain exposed.

Marcus ChenMar 24, 2026
CanisterWorm Adds Iran-Targeting Kubernetes Wiper
Malware4 min read

CanisterWorm Adds Iran-Targeting Kubernetes Wiper

TeamPCP's supply chain attack expands with a Kubernetes wiper that detects Iranian systems via timezone and locale, wiping clusters while backdooring everyone else.

James RiveraMar 23, 2026
AVideo RCE Chain Gives Attackers Full Server Access Without Auth
Vulnerabilities3 min read

AVideo RCE Chain Gives Attackers Full Server Access Without Auth

Three vulnerabilities in AVideo's CloneSite plugin chain together for unauthenticated remote code execution. CVE-2026-33478 has no patch available as attackers can extract admin credentials and inject OS commands.

Marcus ChenMar 23, 2026
Ubuntu Desktop Flaw Lets Local Users Escalate to Root
Vulnerabilities3 min read

Ubuntu Desktop Flaw Lets Local Users Escalate to Root

CVE-2026-3888 exploits timing race between snap-confine and systemd-tmpfiles to grant root access on Ubuntu Desktop 24.04+. Qualys researchers demonstrate full privilege escalation.

Marcus ChenMar 23, 2026
Navia Benefit Solutions Breach Exposes 2.7 Million SSNs
Data Breaches3 min read

Navia Benefit Solutions Breach Exposes 2.7 Million SSNs

Workplace benefits administrator Navia discloses data breach affecting 2.7 million individuals. Social Security numbers, health plan data, and personal information stolen during December-January intrusion.

Sarah MitchellMar 23, 2026

Security Guides

Learn about ransomware, phishing, malware, and essential online safety practices.

Recommended Resources

Curated books, tools, and resources to deepen your cybersecurity knowledge.

Stay Informed

Get the latest cybersecurity news delivered to your inbox.

We respect your privacy. Unsubscribe anytime.